CVE-2021-26629

Publication date

2022-04-26 18:17:48

Family

krcert

State

PUBLISHED

Description

A path traversal vulnerability in XPLATFORMs runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..’.